From systems of record to Day-1-ready accounts
Aquera Identity Sourcing connects every system of record, HCM, candidate recruiting, contract and contingent worker sources, and B2B partner users, to your directories. Records are correlated, transformed, and synchronized into Active Directory and cloud-only users, then flow onward to Microsoft 365. No scripting, no manual tickets.
Trusted by 1,500+ Organizations Worldwide
Your systems of record decide who. Aquera delivers the accounts
Every hire, transfer, and termination becomes the right accounts, group memberships, and licenses, on Day 1, in the user's local time zone.
Solving the sourcing gap
Identity Sourcing datasheet
Correlation, transformation maps, username generation, group membership rules, Microsoft 365 automation, and the full deployment flow.
HR-driven identity sourcing, with audit-grade operational control
Correlate & Link
AI and ML algorithms with a review workbench match each record to one directory account, fuzzy-matching the rest and excluding service accounts.
Transformation Maps
Source attributes with transform logic mapped to target fields, uppercasing, concatenation, and lookups, generated then reviewed and refined.
Username Generation
Pattern-based unique usernames checked against Active Directory, Okta, Entra ID, and databases before writing UPN, email, and samAccountName.
Group Membership
Analyze in-scope groups, generate candidate rules from attributes such as department and cost center, and automate adds and removals.
One resolved identity per person, with Master Identity Index
The same person can arrive from several systems of record: a contractor who converts to employee, a rehire, a partner user with an HCM record. Sourcing each feed independently creates duplicates.
With multiple systems of record feeding Identity Sourcing, Aquera Master Identity Index correlates identities across every source, links them into one durable record per entity, and assigns a single persistent anchor ID that is stamped into every connected system. Correlation becomes a deterministic, upstream fact that every directory account inherits. Records survive departure, so returners re-match to their existing identity instead of being recreated as orphans.
How they work together: Systems of record feed MII → MII resolves each person to one anchor ID → Identity Sourcing provisions and synchronizes the resolved identity into your directories.
Cross-Source Correlation
Resolve and link identities across HR, ATS, contractor, partner, and volunteer systems into one record per entity, human and non-human.
Persistent Anchor ID
One durable anchor ID per identity, written to stable attributes, so accounts stay correlated across renames, moves, rehires, and tenure gaps.
Link & Unlink History
Merge records that are the same person; split bad matches without losing history. Audits see what was linked, when, and why.
Everything that has to be right for Day 1 to actually work
Early Onboarding
To-be-hired and pre-hire records create accounts early for validation, with joiner tickets raised in your ITSM for Day-1 readiness.
Time-Zone Aware Actions
Actions trigger on the user’s local time, not the admin’s, with configurable offsets and future-dated scheduling.
Full Microsoft 365 Automation
Licenses, distribution lists, shared mailboxes, and OneDrive on join; mailbox conversion, session revocation, and device cleanup on exit.
Incremental Sync
Fault-resilient polling with no store and forward. Aquera tracks queue position and advances only on success, over TLS-encrypted transfers.
Fail-Safe Controls
Transaction approval rules, thresholds, and exception handling with recommendations protect directories from runaway changes.
Operations Center
Transaction analysis and approvals, forensics search, savings analysis, and unified logging, every action audited.
Generated configuration, not a custom integration project
Integration analysis
Aquera analyzes record linking, attribute transformation, and group membership using AI and ML algorithms with a review workbench.
Generated configuration
Linked systems of record, transformation maps, group assignment rules, username patterns, and reference lookups, generated rather than hand-coded.
Operational configuration
Schedules, notifications, fail-safes, time-of-day on/offboarding, attribute writebacks, and shared resource cleanup at offboarding.
See Identity Sourcing in Action
A 30-minute working session mapped to your systems of record, scoped to what you actually run.
Frequently asked questions
What is Aquera Identity Sourcing? +
Aquera Identity Sourcing is an HR-driven identity automation engine that connects every system of record, HCM, candidate recruiting (ATS), contract and contingent worker systems of record, B2B partner user systems of record, and non-employee identity management, to your directories. Records are correlated, transformed, and synchronized into Active Directory users and cloud-only users in Okta or Entra ID, then flow onward to Microsoft 365, with no scripting and no manual tickets.
What problem does Aquera Identity Sourcing solve? +
Identity lives in many places: employees, candidates, contractors, partners, and non-employees each arrive from a different system of record, directory records without a unique identifier get matched by hand, and accounts appear after start dates or linger after terminations. Identity Sourcing automates correlation, attribute transformation, unique username generation, group membership, and on/offboarding timing so every hire, transfer, and termination produces the right accounts, group memberships, and licenses on Day 1, in the user’s local time zone.
How does Aquera Identity Sourcing work? +
Systems of record feed Aquera’s identity sourcing automation, which correlates, transforms, and syncs each record into your directories. Accounts are created as Active Directory users and/or cloud-only users, with AD accounts synchronized onward to Entra ID or Okta and Microsoft 365. The result is Day-1 readiness through early onboarding, on/offboarding at the user’s correct local time, and fault-resilient incremental sync with no store and forward.
What are the core capabilities of Aquera Identity Sourcing? +
Four core capabilities: Correlate and Link, Transformation Maps, Username Generation, and Group Membership, backed by incremental sync, fail-safe controls, and the Aquera Operations Center.
Which systems of record does Aquera Identity Sourcing support? +
HCM platforms, candidate recruiting (ATS) systems, contract and contingent worker systems of record, B2B partner user systems of record, and non-employee identity management systems, all feeding one sourcing engine.
Which directories and identity platforms does it provision? +
Aquera Identity Sourcing provisions Active Directory users and cloud-only users in Okta or Entra ID, and synchronized identities flow onward from Active Directory to Entra ID or Okta and Microsoft 365, covering office workers in AD and frontline, cloud-only users.
Can Aquera provision cloud-only users for frontline workers? +
Yes. Frontline workers are provisioned as cloud-only users in Okta or Entra ID, while office workers receive Active Directory accounts, and AD users receive group, attribute, and Microsoft 365 offboarding updates.
How does Aquera correlate HR records with existing directory accounts? +
AI and ML matching algorithms with a review workbench link each system-of-record entry to one and only one directory record. Aquera first matches on unique identifiers such as employee number, fuzzy-matches the remainder on attributes like name and email, writes the employee number back into matched records, and excludes out-of-scope records such as service accounts.
How do attribute transformation maps work? +
Aquera generates an attribute transformation map for each target: source HCM fields with transform logic, uppercasing, concatenation, and reference lookups, mapped to target directory fields across multiple targets. Generated mappings are then reviewed, modified, or excluded as required.
How does Aquera generate unique usernames? +
From preferred patterns, comparing each candidate against reference user stores including Active Directory domains, Okta, Entra ID, and databases, before writing the unique value to fields such as User Principal Name, email address, samAccountName, and Common Name.
How does Aquera automate directory group membership? +
Aquera analyzes in-scope directory groups, generates candidate membership rules from user attributes such as department, branch, and cost center, and automates group adds and removals, driving downstream application assignments from directory group membership.
How does Aquera ensure new hires are ready on Day 1? +
Early onboarding: to-be-hired candidates from the ATS recruiting module and pre-hire status employees from core HR create accounts early for validation or review, generate joiner tickets in IT Service Management, and initiate any manual processes, so access is ready on Day 1.
Does Aquera support time-zone aware onboarding and offboarding? +
Yes. Account creation, notification, and deactivation trigger at the user’s correct local time in every office, not the admin’s time zone, with configurable HCM-aligned offsets and future-dated scheduling. Actions can run a set number of days before or after the hire or termination date.
What happens when identities come from multiple sources? +
The same person can arrive from several systems of record, a contractor who converts to employee, a rehire, or a partner user with an HCM record, and sourcing each feed independently creates duplicates. With multiple sources feeding Identity Sourcing, Aquera Master Identity Index correlates identities across every source, links them into one durable record per entity, and assigns a single persistent anchor ID stamped into every connected system.
How do Identity Sourcing and Master Identity Index work together? +
Systems of record feed Master Identity Index; MII resolves each person to one anchor ID; Identity Sourcing provisions and synchronizes the resolved identity into your directories. Correlation becomes a deterministic, upstream fact that every directory account inherits, and records survive departure so returners re-match to their existing identity instead of being recreated as orphans.
What does Aquera automate in Microsoft 365? +
On join: creating cloud-only users, updating existing users, assigning group memberships and Microsoft 365 licenses, and creating distribution lists, shared mailboxes, and shared OneDrive locations. On exit: mailbox conversion to shared with auto-reply and manager forwarding, session revocation, removal of group memberships, app roles and delegations, device cleanup including Intune-managed devices, manager access to OneDrive, license reclaim with reassignment logic, and litigation hold support.
How does Aquera keep directories in sync with HR systems? +
Incremental sync polls the system of record for changes using a last-modified queue, retrieves the full changed record by ID, and synchronizes directory attributes and group assignments, tracking its position in the queue and advancing only when an update succeeds.
Is Aquera Identity Sourcing fault tolerant? +
Yes. A fault-resilient architecture with no store and forward: data is not queued in intermediate storage, transfers are TLS encrypted, notifications report sync activity, and the engine updates its queue position only when a change is applied successfully.
What fail-safe controls does it provide? +
Fail-safe controls with transaction approval rules and thresholds, plus exception handling with recommendations and actions, protecting directories from runaway or unintended changes before they are applied.
How is Aquera Identity Sourcing deployed? +
Deployment starts with integration analysis, then generates the configuration: linked systems of record, transformation maps across multiple targets, group assignment rules, unique username generation, and reference data lookup tables. Operational configuration follows: schedules, notifications, fail-safe controls, time-of-day on/offboarding, attribute writebacks, and shared resource cleanup with offboarding.
Does Aquera require scripting or manual tickets? +
No. Records from your systems of record are correlated, transformed, and synchronized into your directories automatically. Configuration is generated, then reviewed and refined, rather than coded by hand.
How do I see a demo of Aquera Identity Sourcing? +
Contact your Aquera representative or email sales@aquera.com, or visit aquera.com, to see Identity Sourcing live, from your systems of record to Day-1-ready, correctly correlated directory accounts.